ROOTREPEAL (c) AD, 2007-2009 ================================================== Scan Start Time: 2011/09/19 21:18 Program Version: Version 1.3.5.0 Windows Version: Windows XP SP3 ================================================== Drivers ------------------- Name: dump_atapi.sys Image Path: H:\WINDOWS\System32\Drivers\dump_atapi.sys Address: 0xB62F6000 Size: 98304 File Visible: No Signed: - Status: - Name: dump_WMILIB.SYS Image Path: H:\WINDOWS\System32\Drivers\dump_WMILIB.SYS Address: 0xBA5F8000 Size: 8192 File Visible: No Signed: - Status: - Name: rootrepeal.sys Image Path: H:\WINDOWS\system32\drivers\rootrepeal.sys Address: 0xB3718000 Size: 49152 File Visible: No Signed: - Status: - Hidden/Locked Files ------------------- Path: H:\hiberfil.sys Status: Locked to the Windows API! Path: H:\Program Files\Yahoo! Games\THE GAME OF LIFE - PTS\THE GAME OF LIFE - Path to Success.exe:{8DB68326-B33C-2003-EAD5-C674A2BC6D98} Status: Visible to the Windows API, but not on disk. Path: h:\documents and settings\willsons\application data\skype\etilqs_32qhgovjltvv3dsutbuf Status: Allocation size mismatch (API: 65536, Raw: 0) Path: h:\documents and settings\willsons\application data\skype\etilqs_f71e9tfxqoq0yh9v3uxe Status: Allocation size mismatch (API: 4096, Raw: 0) Path: h:\documents and settings\willsons\application data\skype\etilqs_ozhasftaxm9d5nqvzalh Status: Allocation size mismatch (API: 4096, Raw: 0) Path: h:\documents and settings\willsons\application data\skype\etilqs_rb9zpmqdecj6incdmpdi Status: Allocation size mismatch (API: 4096, Raw: 0) Path: h:\documents and settings\willsons\application data\skype\etilqs_syfpbcbw3hnxxqcnupt0 Status: Allocation size mismatch (API: 32768, Raw: 0) Path: h:\documents and settings\willsons\application data\skypepm\2011-09-19-2.ezlog Status: Size mismatch (API: 22720, Raw: 22592) Path: H:\Documents and Settings\Willsons\Desktop\THE GAME OF LIFE(TM) by Hasbro\THE GAME OF LIFE(TM) by Hasbro.exe:{A1D8DC1C-4669-B386-A8F2-2157B5CC421B} Status: Visible to the Windows API, but not on disk. Path: h:\documents and settings\willsons\local settings\temp\etilqs_df80v5amlr5o6a2 Status: Allocation size mismatch (API: 32768, Raw: 0) Path: h:\documents and settings\willsons\local settings\temp\etilqs_tkfxomgu8czuqf4 Status: Allocation size mismatch (API: 32768, Raw: 0) Path: h:\documents and settings\willsons\application data\skype\aljam2\etilqs_2sqfmrouoeply3c48e7h Status: Allocation size mismatch (API: 4096, Raw: 0) Path: h:\documents and settings\willsons\application data\skype\aljam2\etilqs_teny46hmrcgmodl6a6pb Status: Allocation size mismatch (API: 16384, Raw: 0) ==EOF==